CVE-2026-43944Disclosure(electerm_project / electerm)

LOWCVSS 9.6 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerable to arbitrary local code execution via deep links, CLI --opts, or crafted shortcuts. Exploit requires clicking a crafted electerm://... link or opening a crafted shortcut/command that launches electerm with attacker-controlled opts. This issue has been patched in version 3.8.15.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-94CWE-829

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • electerm

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-05-14)
  • 4 total mentions across 3 days

Affected systems

Products
electerm

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-08: 1Mentions · 2026-05-10: 1Mentions · 2026-05-14: 2Technical Details · 2026-05-08: 1Technical Details · 2026-05-14: 105-0805-1005-14
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-081
Disclosure1
2026-05-101
Disclosure1
2026-05-142
General2
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    General

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CRITICAL: CVE-2026-43944 (CVSS 9.6) — electerm project electerm

    Post summary

    The post merely cites a critical CVE with its CVSS score but provides no further technical details or actionable information.

    1000024
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-43944-electerm-project-electerm #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text only contains a URL and hashtags, with no concrete evidence of exploitation, PoC, or mitigation information.

    0000020
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-43944 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerable to arbitrary lo… https://www.cve.org/CVERecord?id=CVE-2026-43944

    Post summary

    The post announces a vulnerability (CVE-2026-43944) in electerm but provides no substantive technical details, PoC, exploit, or patch information, and makes no claims of active exploitation.

    00000133
    57.5K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Electerm, Arbitrary Code Execution, #CVE-2026-43944 (Critical) https://dailycve.com/electerm-arbitrary-code-execution-cve-2026-43944-critical/

    Post summary

    The text announces the disclosure of a critical CVE that enables arbitrary code execution, but provides no further technical or exploit information.

    0000031
    198 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appelecterm_projectelecterm---

Explore more